LOW 3.7 PyPI

Flask-AppBuilder Observable Response Discrepancy

GHSA-p8q5-cvwx-wvwp · CVE-2025-24023 · PYSEC-2025-15

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

User enumeration in database authentication in Flask-AppBuilder <= 4.5.3 and werkzeug >= 3.0.0. Allows for a non authenticated user to enumerate existing usernames by timing the response time from the server when brute forcing requests to login.

Patches

Upgrade to flask-appbuilder>=4.5.3

Workarounds

Downgrade werkzeug to <3.0.0

References

Are there any links users can visit to find out more?

Ready to move

Start Securing

Free, no credit card | First findings in minutes